See this document in CiteSeerX!

The Insecurity of the Digital Signature Algorithm with Partially Known Nonces (2000)  (Make Corrections)  (34 citations)
Phong Q. Nguyen, Igor E. Shparlinski



  Home/Search   Context   Related

 
View or download:
mq.edu.au/~igor/DSA.ps
Cached:  PS.gz  PS  PDF   Image  Update  Help

From:  mq.edu.au/~igor/Publ (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: We present a polynomial-time algorithm that provably recovers the signer's secret DSA key when a few bits of the random nonces k (used at each signature generation) are known for a number of DSA signatures at most linear in log q (q denoting as usual the small prime of DSA), under a reasonable assumption on the hash function used in DSA. The number of required bits is about log 1/2 q, and can be further decreased to 2 if one assumes access to ideal lattice basis reduction, namely an oracle for... (Update)

Cited by:   More
On the Provable Security of an Efficient RSA-Based.. - Steinfeld, Pieprzyk.. (2006)   (Correct)
One-Time HNP or Attacks on a Flawed El Gamal Revisited - Rosa (2005)   (Correct)
Experimenting with Faults, Lattices and the DSA - Naccache, Nguyen, Tunstall.. (2005)   (Correct)

Similar documents (at the sentence level):
48.4%:   The Insecurity of the Digital Signature Algorithm with.. - Nguyen, Shparlinski (2000)   (Correct)
22.5%:   The Insecurity of the Elliptic Curve Digital Signature.. - Nguyen, Shparlinski (2000)   (Correct)

Active bibliography (related documents):   More   All
0.6:   Lattice Reduction in Cryptology: An Update - Nguyen, Stern (2000)   (Correct)
0.4:   Generalized Compact Knapsacks, Cyclic Lattices, and Efficient.. - Micciancio (2004)   (Correct)
0.4:   The Two Faces of Lattices in Cryptology - Nguyen, Stern (2001)   (Correct)

Similar documents based on text:   More   All
0.6:   Cryptanalysis of MQV with partially known nonces - Leadbitter, Smart (2002)   (Correct)
0.5:   Hidden Number Problem in Small Subgroups - Shparlinski, Winterhof (2003)   (Correct)
0.5:   Distribution Of Modular Sums And The Security Of The Server .. - Nguyen, Shparlinski (2000)   (Correct)

Related documents from co-citation:   More   All
16:   Hardness of Computing the Most Significant Bits of Secret Keys in Diffie-Hellman.. (context) - Boneh, Venkatesan
14:   The insecurity of the elliptic curve Digital Signature Algorithm with partially .. - Nguyen, Shparlinski - 2000
11:   Lattice attacks on digital signature schemes (context) - Howgrave-Graham, Smart - 2001

BibTeX entry:   (Update)

P. Nguyen and I. E. Shparlinski, `The insecurity of the Digital Signature Algorithm with partially known nonces', Preprint , 2000, 1--18. http://citeseer.ist.psu.edu/article/nguyen00insecurity.html   More

@misc{ nguyen00insecurity,
  author = "P. Nguyen and I. Shparlinski",
  title = "The insecurity of the Digital Signature Algorithm with partially known
    nonces",
  note = "Preprint , 2000, 1--18.",
  year = "2000",
  url = "citeseer.ist.psu.edu/article/nguyen00insecurity.html" }
Citations (may not include all citations):
1065   Handbook of Applied Cryptography (context) - Menezes, Van Oorschot et al. - 1997
659   Random oracles are practical: a paradigm for designing e#cie.. - Bellare, Rogaway - 1993
309   Random number generation and quasi--Monte Carlo methods (context) - Niederreiter - 1992
239   Cryptography: Theory and Practice (context) - Stinson - 1995
186   A public key cryptosystem and a signature scheme based on di.. (context) - Gamal - 1985
115   Uniform distribution of sequences (context) - Kuipers, Niederreiter - 1974
88   cient signature generation by smart cards (context) - Schnorr - 1991
66   On Lovasz lattice reduction and the nearest lattice point pr.. (context) - Babai - 1986
60   Lattice basis reduction: improved practical algorithms and s.. - Schnorr, Euchner - 1994
55   Hardness of computing the most significant bits of secret ke.. (context) - Boneh, Venkatesan - 1996
27   Character sums with exponential functions and their applicat.. (context) - Konyagin, Shparlinski - 1999
20   Factoring polynomials with rational coe#cients (context) - Lenstra, Lenstra et al. - 1982
19   Lattice reduction in cryptology: An update - Nguyen, Stern - 2000
19   FIPS Publication 186: Digital Signature Standard (context) - of, Technology - 1994
18   Hidden collisions on DSS - Vaudenay - 1996
17   discrepancies and applications (context) - Drmota, Tichy - 1997
14   Security of the most significant bits of the Shamir message .. (context) - Vasco, Shparlinski - 2000
13   A hierarchy of polynomial lattice basis reduction algorithms (context) - Schnorr - 1987
13   Design validations for discrete logarithm based signature sc.. - Brickell, Pointcheval et al. - 2000
11   Lattice attacks on digital signature schemes (context) - Howgrave-Graham, Smart - 1999
11   Pseudo-random (context) - Bellare, Goldwasser et al. - 1997
11   The dark side of the hidden number problem: Lattice attacks .. (context) - Nguyen - 2000
5   Number Theory C++ Library (context) - Shoup
4   Exponential sums and goppa codes (context) - Moreno, Moreno - 1991
3   Private communication (context) - Bleichenbacher - 1999
3   the uniformity of distribution of the El Gamal signature - Shparlinski - 2000
3   Breaking knapsack cryptosystems by max-norm enumeration (context) - Ritter - 1996



The graph only includes citing articles where the year of publication is known.


Documents on the same site (http://www.comp.mq.edu.au/~igor/Publ.html):   More
A Lower Bound for Primality - Allender, Saks, Shparlinski (1999)   (Correct)
Finding Points on Curves over Finite Fields - Gathen, Shparlinski, Sinclair (1996)   (Correct)
A Public Key Cryptosystem Based On Sparse Polynomials - Grant, Lieman, Shparlinski (1998)   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC